Nova Scotia investigating theft of personal info through file transfer service MoveIt
Advertisement
Read this article for free:
or
Already have an account? Log in here »
To continue reading, please subscribe:
Digital Subscription
One year of digital access for only $205*
- Enjoy unlimited reading on winnipegfreepress.com
- Read the E-Edition, our digital replica newspaper
- Access News Break, our award-winning app
- Play interactive puzzles
*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.
To continue reading, please subscribe:
Add Free Press access to your Brandon Sun subscription for only an additional
$1 for the first 4 weeks*
- Enjoy unlimited reading on winnipegfreepress.com
- Read the E-Edition, our digital replica newspaper
- Access News Break, our award-winning app
- Play interactive puzzles
*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.
Read unlimited articles for free today:
or
Already have an account? Log in here »
Hey there, time traveller!
This article was published 04/06/2023 (1174 days ago), so information in it may no longer be current.
The Nova Scotia government says it is investigating the theft of personal information stolen through a global privacy breach to a third-party file transfer system the province was using.
The province has yet to determine what information may have been taken or how many Nova Scotians could be affected by the breach to software company MoveIt’s products, Cyber Security and Digital Solutions Minister Colton LeBlanc said in a Sunday news conference.
“At this time, staff are manually going through all of the files that were accessed to identify what information was stolen and who it belongs to,” he said.
“Until all of this work is complete, we aren’t able to say how many Nova Scotians have been impacted.”
The MoveIt software made by Burlington, Massachusetts-based company Ipswitch allows organizations to transfer files and data between employees, departments and customers.
Progress Software, the parent company of Ipswitch, confirmed a vulnerability in its software last week, saying the issue could lead to potential unauthorized access of users’ systems and files.
But the company notified the province of a critical vulnerability within its system on Thursday, LeBlanc said.
The province then took the service offline and installed a security update before bringing it back online Friday, only to be told further investigation was needed. Cyber security experts were then called in.
On Saturday evening.
LeBlanc said the investigation gave the province “a high degree of confidence that yes, there has been a breach of personal information.”
“We did not want to wait for all the answers before we told Nova Scotia what we are dealing with,” he said.
“I know there are questions we can’t answer right now because we’re still analyzing the full extent.”
LeBlanc would not say which departments had been using MoveIt or whether he was aware of other provinces or territories affected by the breach.
He said the province has informed Tricia Ralph, Nova Scotia’s information and privacy commissioner, of the breach and intends to create a website offering the public more information on the situation.
He also promised the province will directly notify Nova Scotians who have been impacted.
“I know that this is a stressful time for many Nova Scotians right now and I want to reassure all Nova Scotians that we are working tirelessly to resolve this issue as quickly and as efficiently as possible,” LeBlanc said.
Progress Software did not answer questions about how many Canadians may be affected and what other governments or businesses in the country have used its products.
But it said it promptly launched an investigation after discovering a vulnerbility, alerted customers, provided immediate mitigation steps and developed a security patch within 48 hours.
“We are also continuing to work with industry-leading cybersecurity experts to investigate the issue and ensure we take all appropriate response measures,” the company said in an email.
This report by The Canadian Press was first published June 4, 2023.